PT-2025-51850 · Unknown · Keepassxc-Browser
Justvraj04
·
Published
2025-12-17
·
Updated
2026-01-05
·
CVE-2025-65203
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
KeePassXC-Browser versions through 1.9.9.2
Description
The software autofills or prompts users to fill stored credentials into documents rendered under a browser-enforced Content Security Policy (CSP) directive and iframe attribute sandbox. This allows attacker-controlled script within the sandboxed document to access populated form fields and potentially exfiltrate credentials.
Recommendations
Update to a version later than 1.9.9.2.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keepassxc-Browser